A public disclosure reported that wolfSSL versions 5.7.2 through 5.9.0-stable contain a flaw in the ML-DSA-44 signing path that frees a heap buffer holding private signing material without clearing it first. In native ML-DSA builds enabled with --enable-mldsa or --enable-dilithium, a same-process attacker can recover secret key material from reused heap memory and forge signatures on arbitrary messages. Researcher Abhinav Agarwal demonstrated end-to-end signature forgery on Linux and macOS, with forged signatures accepted by wc_dilithium_verify_msg() in compiled libwolfssl binaries.
wolfSSL confirmed the issue and addressed it through fixes referenced in pull requests #10100 and #10113, with the remediation shipping in wolfSSL 5.9.1-stable. The vendor did not assign a CVE and reportedly classified the finding as a bug rather than a vulnerability, even as its broader release advisory warned of multiple cryptographic verification weaknesses affecting certificate validation and signature handling. The disclosure also noted that similar missing-memory-clearing problems had previously been corrected in wolfSSL code paths for Dilithium key generation, Ed25519 signing, and Ed448 signing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
wolfSSL published release 5.9.1-stable, which includes fixes for multiple security issues and is the release recommended for users to update to. The release follows the ML-DSA disclosure and broader advisory covering certificate verification, parsing, TLS/DTLS, and cryptographic verification flaws.
A public disclosure on oss-security/openwall described the same-process heap reuse issue in wolfSSL and noted that forged signatures were accepted by wc_dilithium_verify_msg() in compiled libwolfssl binaries. wolfSSL confirmed the finding, said fixes were made in pull requests #10100 and #10113, and no CVE was assigned because the vendor classified it as a bug rather than a vulnerability.
Abhinav Agarwal found that wolfSSL's ML-DSA-44 signing path frees a heap buffer containing private signing material without zeroing it, allowing a same-process attacker to recover key material from reused memory and forge signatures. The issue affects native ML-DSA builds in wolfSSL versions 5.7.2 through 5.9.0-stable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceseclists.org
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.